Impact
A weakness has been identified in gedelumbung HospitalManagement up to commit c2d45543789a3887067d3915f69d44cfc2cf76a8 that allows attackers to perform cross‑site request forgery (CSRF). The flaw permits an attacker to trick a legitimate user into submitting unwanted requests to the application, potentially leading to unauthorized state changes. This attack exploits the absence of CSRF protections and, according to the CWE mapping, relates to CWE‑352 and possibly a missing authorization check (CWE‑862).
Affected Systems
The vulnerability affects the gedelumbung HospitalManagement application, represented by the vendor/product pair gedelumbung:HospitalManagement. Because the project uses a rolling‑release model, specific version numbers for affected or patched releases are not available, but all instances prior to commit c2d45543789a3887067d3915f69d44cfc2cf76a8 are potentially vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, so it is not yet known to be actively exploited in the wild. Based on the description, it is inferred that the attack requires an attacker to entice an authenticated user to visit a malicious site or click a link, after which the victim’s session is used to perform state‑changing requests. The public availability of an exploit and the ability to launch the attack remotely suggest that an attacker with a legitimate session could gain unintended access. The risk is contingent on users interacting with untrusted sites while authenticated, and on the presence of state‑changing actions that lack proper CSRF defenses.
OpenCVE Enrichment